Feds once again fix up compromised retail routers under court order.
Encrypt-Keeper
link
fedilink
English
39
edit-2
8M

An important detail to mention is that every router involved were very old Ubiquiti EdgeRouters which were EOL’d like a year or two ago and they had remote administration enabled and were still using the default admin user and password.

I was running an edge router x until a few months ago. It was the cheapest set up to deploy a unifi wireless access point for my apartment. I was worried until I read:

It affected routers running Ubiquiti’s EdgeOS, but only those that had not changed their default administrative password. Access to the routers allowed the hacking group to “conceal and otherwise enable a variety of crimes,” the DOJ claims, including spearphishing and credential harvesting in the US and abroad.

Change you default passwords friends. Given that the edge router is not the most noob friendly device to set up, I’m curious how the user base of these devices is not changing the PW.

@lemonuri@lemmy.ml
link
fedilink
English
68M

I think it’s best to only buy routers supporting openwrt in the first place and switch firmware to openwrt asap. Openwrt or Opnsense or anything open source and well maintained will guarantee security updates years and years beyond the original manufactures firmware.

jelloeater - Ops Mgr
link
fedilink
English
38M

Have you ever used a EdgeRouter?

@lemonuri@lemmy.ml
link
fedilink
English
18M

No, but openwrt seems to be available for some of their models if that is your question.

@umbrella@lemmy.ml
link
fedilink
English
33
edit-2
8M

DOJ should quietly remove US malware too

Create a post

This is a most excellent place for technology news and articles.


Our Rules


  1. Follow the lemmy.world rules.
  2. Only tech related content.
  3. Be excellent to each another!
  4. Mod approved content bots can post up to 10 articles per day.
  5. Threads asking for personal tech support may be deleted.
  6. Politics threads may be removed.
  7. No memes allowed as posts, OK to post as comments.
  8. Only approved bots from the list below, to ask if your bot can be added please contact us.
  9. Check for duplicates before posting, duplicates may be removed

Approved Bots


  • 1 user online
  • 210 users / day
  • 601 users / week
  • 1.38K users / month
  • 4.49K users / 6 months
  • 1 subscriber
  • 7.41K Posts
  • 84.7K Comments
  • Modlog